Skip to content

Security: forge-builder/aurel

SECURITY.md

Security policy

Reporting a vulnerability

Use GitHub private vulnerability reporting when available.

If private reporting is unavailable, open a minimal public issue that says a private security report is needed. Do not include exploit details, credentials, customer data, private keys, wallet material, or recovery secrets in a public issue.

Scope

Security reports are welcome for checked-in code, workflows, validators, public documentation that creates a concrete unsafe behavior, and repository configuration under this project's control.

General claims about unrelated repositories, private runtime state, or third-party services are outside this repository's authority unless a direct reproducible link is provided.

Response posture

A valid report should receive:

  1. acknowledgement;
  2. reproduction or a clearly recorded blocker;
  3. severity and blast-radius assessment;
  4. smallest safe fix;
  5. verification and public-safe disclosure decision.

No security guarantee is implied by this policy or by a passing repository validator.

There aren't any published security advisories